Synopsis
The remote web server is affected by an information disclosure vulnerability.
Description
Apache Tomcat (prior to 3.3.1a) is affected by a directory listing and file disclosure vulnerability.
By requesting URLs containing a null character, remote attackers can list directories even when an index.html or other file is present or obtain unprocessed source code for a JSP file.
Also note that, when deployed with JDK 1.3.1 or earlier, Tomcat allows files outside of the application directory to be accessed because 'web.xml' files are read with trusted privileges.
Solution
Upgrade to Tomcat 3.3.1a or higher.
Plugin Details
Nessus ID: 11438
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N
Vulnerability Information
CPE: cpe:/a:apache:tomcat
Patch Publication Date: 3/18/2003
Vulnerability Publication Date: 1/25/2003